Lucas Carpio - Jumil Ortiz
•For example:
SELECT Count (*) FROM Users WHERE UserNaME = 'test@test.com' or 1=1--' AND Password=''
SQL Injection and Server-Side Tecnologies
Exploit databases stored procedures.
Select * FROM users WHERE name = 'x' AND userid IS NULL; --;
Select * FROM users WHERE name = '' or '1' = '1' ;
SELECT name , phone, address FROM users WHERE id=1 UNION ALL SELECT credictCardNumber ,1,1 FROM CreditCardTable
When the results are not visible to the attacker.
Rather than see an useful error message, show a generic message custom message.
Become a time-intensive because a new statement must be crafted for each bit recovered.
•Learn SQL! (pro way)
•Or
•Use prebuilt programs (SQLmap)